Fallos del tipo CWE-125

5126 resultados

Leitura fora dos limites do buffer

Ocorre quando o código tenta acessar dados além das fronteiras válidas de um buffer (array, string, estrutura), lendo memória que não deveria. O risco é expor informações sensíveis da memória adjacente ou causar crash da aplicação.

Ejemplo

Uma função que processa strings sem validar o tamanho da entrada pode ler bytes além do final da string alocada, vazando dados de memória ou causando segmentation fault. Exemplo: strcpy() copiando para buffer menor sem checagem.

Cómo mitigar

Use funções seguras com limite explícito (strlen com buffer_size, strncpy, snprintf), valide índices antes de acessar arrays, e ative verificações de limite em tempo de compilação ou execução (-ftrapv, ASAN, bounds checking).

CVE-2022-2581HIGHOut-of-bounds Read in vim/vimEPSS 0.5%CVE-2026-56099MEDIUMOpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS InputEPSS 0.5%CVE-2026-34876HIGHAn issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows atEPSS 0.5%CVE-2025-59208HIGHWindows MapUrlToZone Information Disclosure VulnerabilityEPSS 0.5%CVE-2025-64899HIGHAcrobat Reader | Out-of-bounds Read (CWE-125)EPSS 0.5%CVE-2026-43630MEDIUMllama.cpp b5702–b7653 Out-of-Bounds Read Information DisclosureEPSS 0.5%CVE-2025-29365CRITICALspimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.EPSS 0.5%CVE-2025-60709HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-7668MEDIUMMikroTik RouterOS SCEP Endpoint scep.p ASN1_STRING_data out-of-boundsEPSS 0.5%CVE-2026-25884LOWExiv2: Out-of-bounds read in CrwMap::decode0x0805EPSS 0.5%CVE-2023-32017HIGHMicrosoft PostScript Printer Driver Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-48688HIGHFastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The functiEPSS 0.5%CVE-2023-24862MEDIUMWindows Secure Channel Denial of Service VulnerabilityEPSS 0.5%CVE-2026-59198MEDIUMPillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated imagesEPSS 0.5%CVE-2026-56193HIGHMicrosoft Office Information Disclosure VulnerabilityEPSS 0.5%CVE-2023-4693MEDIUMGrub2: out-of-bounds read at fs/ntfs.cEPSS 0.5%CVE-2023-39396—Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.EPSS 0.5%CVE-2024-44279MEDIUMAn out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS VeEPSS 0.5%CVE-2026-48092MEDIUM7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116)EPSS 0.5%CVE-2025-32705HIGHMicrosoft Outlook Remote Code Execution VulnerabilityEPSS 0.5%